Security

last person joined: 7 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Clearpass Ports required in multi controller enviroment

This thread has been viewed 4 times
  • 1.  Clearpass Ports required in multi controller enviroment

    Posted Sep 27, 2016 03:36 PM

    Hello

    If i got a  multicontroller enviroment

    I got 2 Controllers Master and stand by

    5 more local controllers

     

    I got a vlan that just exist inthe controller

     

    I configured the Captive portal profile on the master controller i redirect it to the CLEARPASS

     

    Do i need to open the ports just between the Clearpass and Master/Stand by controller?

     

    I dont need to open ports between local controllers and clearpass even if the aps that the clients are connected are on the APS terminated on the local controller?

     

    I belaive i have to open this

    Between Master and Stand by controller

     

    RFC 3576 - UDP port 3799
    RADIUS - UDP port 1812
    RADIUS Accounting Server - UDP port 1813
    HTTP : TCP port 80
    HTTPS: TCP port 443

    Question here(this ports should be bidirectionals???

     

    Also the Clients in vlan 999 that just exist in the controller should have access to clearpass trhoguh the port 80 and 443 so they have access to the clearpass portal.

     

    cheers

    Carlos

     

     

     



  • 2.  RE: Clearpass Ports required in multi controller enviroment

    Posted Sep 28, 2016 11:07 AM

    anyone?



  • 3.  RE: Clearpass Ports required in multi controller enviroment
    Best Answer

    EMPLOYEE
    Posted Sep 28, 2016 11:43 AM

    Any controllers that could have APs on them need to have ports opened between them and clearpass..



  • 4.  RE: Clearpass Ports required in multi controller enviroment

    Posted Sep 28, 2016 12:32 PM

    thank you Collin

    The ports needs to be open bidirectionally???

     

    Cheers

    Carlos